Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bw Webdav HIGH 7.5
CVE-2018-20000

Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks, as demonstrated by an invite-reply document that reads a local file, related to webdav/ser…

Fix: 4.0.3+
Fix from $1,950 2018-12-10
Cas Server HIGH 8.8
CVE-2014-2296

XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 and 3.5.x before 3.5.2.1, when …

Fix: 3.4.12.1 / 3.5.2.1+
Fix from $1,950 2018-07-20
Opencast MEDIUM 6.5
CVE-2017-1000221

In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules and players will handle the …

Fix: after 2.2.3
Fix from $1,600 2017-11-17
Phpcas HIGH 8.1
CVE-2017-1000071

Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS…

Mitigation only
Fix from $1,950 2017-07-17
Central Authentication Service HIGH 7.5
CVE-2015-1169

Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as …

Fix: after 3.5.2
Fix from $1,950 2015-02-10
Phpcas MEDIUM 5.8
CVE-2012-5583

phpCAS before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X…

Fix: after 1.3.1
Fix from $1,600 2014-06-06
Phpcas MEDIUM 6.4
CVE-2010-3692

Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers …

Fix: after 1.1.2
Fix from $1,600 2010-10-07